CWE-266
CVEs classified under CWE-266, newest first.
142 CVEsRSS
CVE-2026-90501Medium· 6.3PoCA security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT
A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. …
CVE-2026-90499Medium· 5.4PoCA security flaw has been discovered in lenve vhr 1.0-SNAPSHOT
A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of the file /hr/pass of the component Password Update Handler. The manipulation of the argument hrid results in improper…
CVE-2026-90507Medium· 6.3PoCA vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46
A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such ma…
CVE-2026-90523High· 7.3PoCA vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09
A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java o…
CVE-2026-90520Medium· 6.3PoCA vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64
A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization I…
CVE-2026-90566High· 7.3PoCA weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f
A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registratio…
CVE-2026-90565Medium· 5.3PoCA security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f
A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid resul…
CVE-2026-90518Medium· 6.3PoCA security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0
A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may …
CVE-2026-90487Medium· 4.3A vulnerability was found in Xuxueli xxl-job up to 3.4.2
A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupController.java. The manipulation result…
CVE-2026-89672High· 7.0⚖ disputedkernel: nfsd: gate nfs2 setacl by argp->mask (CVE-2026-89672)
A flaw was found in the Linux kernel's Network File System (NFS) server daemon (`nfsd`). When processing NFSACL version 2 SETACL requests, the system could unintentionally remove a directory's default Access Control List (ACL) or both acce…
CVE-2026-62102High· 8.8WordPress Gato GraphQL plugin <= 19.2.3 - Privilege Escalation vulnerability
Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.
CVE-2026-62106High· 8.8WordPress SMS Alert Order Notifications plugin <= 3.9.9 - Privilege Escalation vulnerability
Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.
CVE-2026-8303High· 7.8Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5.
Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5.
CVE-2026-81805High· 8.1Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
CVE-2026-15140High· 7.7A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP)
A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped p…
CVE-2026-86804Medium· 5.3A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10
A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the function CPAResource of the file apps/manager-server/internal/http/controller/proxy/handler.go of the component HTTP Handler. The man…
CVE-2026-85400High· 7.5Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands
Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is nor…
CVE-2026-77654Medium· 6.1Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalat…
Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalat…
CVE-2026-86516Medium· 4.7A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0
A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Scri…
CVE-2026-86512Medium· 6.3PoCA vulnerability was identified in java-json-tools json-patch up to 1.13
A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move O…
CVE-2026-81792Medium· 6.5Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions.
Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions.
CVE-2026-86500Medium· 5.5In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin
In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin
CVE-2026-86482High· 8.8In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
CVE-2026-86285Medium· 4.3PoCA vulnerability was detected in BookStack up to 26.05.2
A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attachment Edit Endpoint. T…
CVE-2026-86275Medium· 5.3PoCA vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0
A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manipulation of the argument role results i…
CVE-2026-86228Medium· 4.3PoCA security vulnerability has been detected in JeecgBoot up to 3.9.3
A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/…
CVE-2026-86212Medium· 4.3PoCA vulnerability has been found in Open5GS 2.7.7/2.8.0
A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit has…
CVE-2026-86153Critical· 9.1A vulnerability has been found in Tenda CP3 27.5.57.101
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the at…
CVE-2026-85513Medium· 6.3PoCStackStorm st2 NoOp RBAC backend actionexecutions.py privileges management
A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_user_query_param_is_provided of the file st2api/st2api/controllers/v1/actionexecutions.py of the component NoOp RBAC ba…
CVE-2026-84756High· 7.1Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.
Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.